Policy Evaluation Tool for Access Control Troubleshooting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers face challenges with unintended access denials and allowances in identity management services, leading to security risks, inefficiencies, and frustration due to unclear policy configurations and difficulties in debugging issues.

Innovation Solution

A policy evaluation tool is provided to identify and troubleshoot unintended access denials and allowances by evaluating relevant policies, offering feedback on explicit and implicit denials, and suggesting modifications to resolve access issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If customers manually configure and debug policies to control access, then access control functionality is achieved, but troubleshooting time and complexity increase significantly

Engineering Contradiction:
Improveaccess control accuracyVSAvoidtroubleshooting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a feedback mechanism where the system automatically evaluates policy configurations and provides diagnostic information to customers. When access is denied, the system analyzes the policy evaluation results and returns specific feedback about which policies caused the denial and what changes are needed, eliminating the need for customers to manually debug complex policy interactions.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-diagnosis by automatically evaluating policies against the denied access request and generating troubleshooting information without customer intervention. The system identifies problematic policies, determines whether denials are explicit or implicit, and provides actionable recommendations, allowing the system to serve itself in resolving access issues.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If customers use broad permissions to ensure access, then access availability improves, but security risks increase

Engineering Contradiction:
Improveaccess availabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent dynamically adjusts permission parameters based on actual access needs. Instead of using fixed broad permissions, the system evaluates each access request against specific policy criteria and grants the minimum necessary access. This allows the system to maintain security while providing adequate access by changing permission parameters dynamically rather than using static broad permissions.

Inventive Principle:
Principle #35Parameter changes

3Manufacturing precision

If multiple policies are configured to manage access, then permission granularity improves, but policy complexity and difficulty in identifying conflicting policies increases

Engineering Contradiction:
Improvepermission granularityVSAvoidpolicy configuration complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent segments the policy evaluation process into distinct analytical components. It separately identifies explicit denials, implicit denials, and acceptable policies, presenting each category independently to customers. This segmentation helps customers understand which specific policies are causing access denials without being overwhelmed by the overall complexity of the policy configuration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system acts as an intermediary between the complex policy configuration and the customer. It translates complex policy evaluation results into understandable diagnostic information, identifying which policies cause denials and what changes are needed. This intermediary function simplifies the customer's interaction with complex policies while maintaining the granularity benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If automatic policy evaluation is implemented, then troubleshooting efficiency improves, but system complexity increases

Engineering Contradiction:
Improvetroubleshooting efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary evaluation of policies against potential access requests before actual access attempts. By pre-evaluating policy configurations and identifying potential denial scenarios, the system prepares troubleshooting information in advance, significantly improving troubleshooting efficiency when access issues occur without requiring complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12238106B1Troubleshooting policy-based permissions
Publication Date: 2025.02.25 AMAZON TECH INC
  • US12238106B1 patent drawing
  • US12238106B1 patent drawing
  • US12238106B1 patent drawing

AI summary

One or more indications may be received of a decision to deny an attempted access of a computing resource by an identity. A plurality of relevant policies may be determined whose permissions are evaluated as inputs to the decision to deny. One or more denial-related policies of the relevant policies may be determined that are associated with at least one of explicitly denying or implicitly denying the attempted access. One or more denial indications may be provided of the one or more denial-related policies. The one or more denial indications may include at least one explicit deny indication of at least one of the one or more denial-related policies that explicitly denies the attempted access. The one or more denial indications may also include at least one implicit deny indication of at least one of the one or more denial-related policies that implicitly denies the attempted access.